whitepaper
The EU AI Act Explained: What Smart Makers Need to Know
Artificial intelligence is rapidly becoming part of modern industrial products, connected equipment and digital services. From predictive maintenance and intelligent automation to AI-powered assistants, organisations are embedding AI into the products they build and the experiences they deliver.
As AI moves from experimentation into everyday operations, expectations are changing.
Customers want to understand how AI reaches decisions, what data it uses, and how outputs are controlled. Regulators expect organisations to demonstrate appropriate governance. Businesses need confidence that innovation is supported by transparency, accountability and trust.
The EU AI Act is Europe’s response to that challenge.
As the world’s first comprehensive legal framework for artificial intelligence, the EU AI Act establishes harmonised rules for AI using a risk-based approach designed to promote trustworthy AI while supporting innovation. Rather than treating every AI application the same, it recognises that different AI systems create different levels of risk—and that responsibilities should reflect those differences.
For Smart Makers, understanding the principles behind the EU AI Act is becoming just as important as understanding the technology itself. The organisations that succeed won’t simply be those adopting AI the fastest—they’ll be the ones building AI that is reliable, explainable, and trusted by customers..
Key takeaways
- The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence.
- Not every software application is considered an AI system under the regulation.
- Responsibilities depend on both the level of risk and on your organisation role in the AI value chain, such as a provider or deployer.
- Building trusted AI means embedding governance alongside innovation from the outset.
Why AI regulation matters now
Artificial intelligence is no longer an emerging technology. It is becoming a core capability within connected products, industrial operations and digital services.
As AI becomes embedded within business-critical processes, organisations face a new challenge. Success is no longer measured solely by what AI can do, but by how responsibly it is developed, deployed and governed.
Customers increasingly want to know what information AI can access, how decisions are made, whether actions can be audited and how sensitive operational data is protected. These questions are becoming part of purchasing decisions, product evaluations and long-term technology strategies.
At the same time, governments around the world are introducing regulatory frameworks designed to support responsible AI adoption.
The EU AI Act is one of the most significant developments in this landscape. For Smart Makers, it represents more than another piece of legislation. It provides a framework for understanding how organisations can continue innovating while building the trust that customers increasingly expect.
Building trusted AI isn’t just about meeting regulatory requirements. It’s about creating AI-enabled products that customers are confident adopting.
Understanding whether the EU AI Act applies to your AI
One of the first questions organisations ask is whether their software is actually considered an AI system under the EU AI Act.
The answer is important because the regulation does not apply to every software application.
Traditional software that simply follows predefined, deterministic rules generally remains outside the scope of the legislation. For example, a rule-based workflow that raises an alarm when a sensor exceeds a fixed threshold or automatically starts a backup pump based on predefined conditions would typically not be considered an AI system. By contrast, systems capable of inferring from data to generate predictions, recommendations, decisions or content are generally considered AI systems under the regulation. Examples include predictive maintenance models that estimate equipment failure, AI assistants that generate troubleshooting guidance, or generative AI that creates reports or code.
For Smart Makers, the key step is to identify which capabilities within a connected product are AI systems under the EU AI Act and which are not. This enables organisations to focus governance, documentation and oversight where they are needed, while continuing to develop deterministic automation using established engineering practices
Trust starts with understanding risk
One of the defining characteristics of the EU AI Act is that it does not regulate every AI application equally.
Instead, it takes a risk-based approach.
The higher the potential impact an AI system could have on people, safety or fundamental rights, the greater the responsibilities placed on organisations developing or deploying that system.
Rather than trying to remember every risk category, the important takeaway is that governance should be proportionate to risk.
Many AI applications currently in use fall into the minimal-risk category and face few additional obligations such as AI used to generate documentation, summarize information or assist developers. Transparency requirements apply to some AI applications that interact directly with people or generate AI-created content, such as chatbots or AI-generated text and images, where users must be informed that AI is involved., while high-risk AI systems require more comprehensive governance, oversight and documentation,particularly when AI performs safety-critical functions, for example:
- Critical infrastructure: AI controlling or protecting electricity, gas, water or heating systems, scheduling maintenance to prevent harm, or executing automated grid isolation.
- Machinery & lifts: AI performing safety functions in industrial machinery or lifts, including machine-learning safety components.
- Medical devices: AI analysing patient data, supporting diagnosis or assisting treatment decisions.
.. At the highest end of the spectrum, certain AI practices are prohibited altogether.
This approach enables organisations to continue innovating while ensuring that additional controls are focused where they can have the greatest impact.
For Smart Makers, understanding risk is less about legal classification and more about recognising where governance should become part of the product development process.
Why your role matters
The responsibilities created by the EU AI Act depend not only on the AI system itself, but also on the role an organisation plays.
The regulation distinguishes several roles, including providers, who develop and place AI systems on the market, and deployers, who use AI systems within their own organisations.
This distinction matters because responsibilities can vary significantly depending on how AI is developed and used.
An organisation using third-party AI tools internally may have very different obligations from one embedding AI capabilities into commercial products.
Importantly, these roles are not always fixed. As AI solutions evolve, so can an organisation’s responsibilities. Integrating third-party AI into your own products, making substantial modifications to an existing high-risk AI system, or repurposing AI for a high-risk use case can shift legal responsibilities under the EU AI Act. Similarly, combining multiple AI components into a solution used in a high-risk domain means the compliance assessment applies to the overall system, not just the individual components. Human oversight must also be meaningful, with people having the information, authority and opportunity to review, challenge or override AI decisions rather than simply approving them.
The key takeaway isn’t memorising legal definitions.
It’s recognising that responsibility extends across the AI value chain. Understanding where your organisation fits within that ecosystem is an important step towards building AI responsibly.
Regardless of role, both providers and deployers need to support staff AI literacy. Equipping teams with role-specific resources ensures a baseline understanding of AI technologies and the context needed for risk-aware operations.
What this means for Smart Makers
For Smart Makers, the most important message of the EU AI Act isn’t the legal terminology.
It’s recognising that governance is becoming part of modern product development.
As AI becomes embedded within connected products and industrial services, organisations will increasingly need to understand where AI is being used, how decisions are made and who is responsible for those systems.
Not every intelligent capability within an AIoT solution will necessarily be considered an AI system. Deterministic automation and rule-based workflows generally remain outside the scope of the regulation, while AI-powered prediction, generative AI and intelligent agents may fall within scope depending on how they are implemented.
When AI capabilities fall within the scope of the EU AI Act—particularly for high-risk applications—governance extends beyond policies into engineering practices. This includes establishing robust risk management, data governance, technical documentation, logging and traceability, transparency for users, meaningful human oversight, cybersecurity and conformity assessments throughout the AI lifecycle. Embedding these capabilities early enables organisations to build trusted AI products while making compliance a natural outcome of good engineering rather than a separate activity.
At Cumulocity, we see this as an opportunity to help customers build connected products with stronger visibility, governance, and control, enabling them to adopt AI with confidence rather than viewing compliance as a barrier to innovation.
Building trusted AI starts with understanding where governance belongs within the AI lifecycle and how it should be applied in practice. Organisations that establish those foundations early will be better positioned to innovate confidently while responding to evolving customer expectations and regulatory requirements.
Preparing for the EU AI Act isn’t simply about compliance.
It’s about building AI-enabled products that customers can trust.
Preparing for the future
The EU AI Act applies in phases, giving organisations time to understand how the regulation applies to their AI initiatives and prepare for future obligations.
Rather than viewing this as a compliance deadline, organisations should see it as an opportunity to strengthen the governance foundations that will support AI innovation over the long term.As AI becomes embedded across connected products and services, organisations should focus on three strategic priorities:
- Understand where AI is being used: Identify which product capabilities fall within the scope of the EU AI Act, distinguish deterministic automation from AI systems, and assess where higher-risk use cases may require additional governance.
- Build governance into product development: Establish governance as part of the product lifecycle by defining responsibilities, implementing appropriate oversight, and creating the documentation and operational visibility needed to support trusted AI.
- Prepare for continuous evolution: The regulatory landscape, customer expectations and AI technologies will continue to evolve. Organisations that establish scalable governance practices today will be better positioned to innovate confidently and adapt as new requirements emerge.
Innovation and trust must evolve together
Artificial intelligence will continue transforming connected products, industrial operations and digital services.
The organisations that succeed won’t simply be those building the most capable AI.
They will be the ones building AI that customers , partners and regulators can trust.
The EU AI Act provides a valuable framework for thinking about that future. By encouraging organisations to consider governance alongside innovation, it supports the development of AI that is transparent, accountable and designed for real-world adoption.
At Cumulocity, we believe trusted AI is built—not added later. By combining secure connectivity, operational visibility, lifecycle management and AI-ready data, we help Smart Makers embed governance into connected products from the start. This enables organisations to innovate with confidence while preparing for evolving regulatory and customer expectations.
Because the future of AI isn’t simply about building more intelligent systems.
It’s about building AI that people trust.
The buyer perspective
Building trusted AI is only one side of the equation. As AI becomes part of connected products and services, customers will increasingly need to understand the implications of the EU AI Act when evaluating and adopting those solutions.
Our companion white paper, The EU AI Act Explained: What Buyers Need to Know, looks at the regulation from the buyer’s perspective, including the questions organisations should consider when assessing AI-enabled products, understanding their responsibilities and working with technology providers.
Read the buyer’s guide to the EU AI Act
How Cumulocity can help
Cumulocity helps Smart Makers turn EU AI Act readiness into a business advantage. As the Act reshapes how connected products and AI-enabled services are developed and governed, Cumulocity provides the operational foundation organisations need to innovate with confidence. By combining secure device connectivity, lifecycle management and AI-ready data, governance becomes an integral part of the product development lifecycle rather than an afterthought.
The result is AI-enabled products and services that are easier to govern, easier to trust and better prepared for evolving customer expectations and regulatory requirements
DISCOVER WHAT CUMULOCITY CAN DO FOR YOUR BUSINESS
Discover how Cumulocity helps organizations connect, manage and scale their AIoT solutions with a demo tailored to your business goals and use case.